Can you get pwned with CSS?
scotthelme.co.uk
scotthelme.co.uk
Without html injection just think about what might be done to disrupt a site. Here on HN you could swap the comments and hide or flag links and make the site unusable. If it were on a page with a delete link or a close account link, you could trick someone into irrecoverable data loss.
Thinking only about key loggers is very narrow thinking.
[1] - https://thejh.net/misc/website-terminal-copy-paste
[2] - https://www.mike-gualtieri.com/css-exfil-vulnerability-teste...
[1]: https://developer.mozilla.org/en-US/docs/Web/CSS/Privacy_and...
It's a clever hack though!
> The window.getComputedStyle method, and similar functions such as element.querySelector, will always return values indicating that a user has never visited any of the links on a page.
> For many years the CSS :visited selector has been a vector for querying a user’s history. It’s not particularly dangerous by itself, but when it’s combined with getComputedStyle() in JavaScript it means that someone can walk through your history and figure out where you’ve been. And quickly – some tests show the ability to test 210,000 URLs per minute. At that rate, it’s possible to brute force a lot of your history or at least establish your identity through fingerprinting. Given that browsers often keep history for a long time it can reveal quite a bit about where you’ve been on the web.
> At Mozilla we’re serious about protecting people’s privacy, so we’re going to fix this problem for our users.
[1] https://hacks.mozilla.org/2010/03/privacy-related-changes-co...
Regardless of it being fixed (thanks for the update) it's still possible to do this via timing attacks. I wouldn't be surprised if the sieve that is a browser still allowed it in some other way.
> For privacy reasons, the styles that can be modified using this selector are very limited.
(and loading a background image isn't one of them).